CVE-2022-42011 is a denial-of-service vulnerability affecting D-Bus versions prior to 1.12.24, 1.14.4, and 1.15.2, including Fedora Project distributions. An authenticated attacker can crash the dbus-daemon and other libdbus-dependent programs by sending a malformed message with an inconsistent array length. This vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring user authentication, and resulting in high availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.12.24CPE matchmatch criteria | cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:* | ||
>= 1.13.0, < 1.14.4CPE matchmatch criteria | cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:* | ||
>= 1.15.0, < 1.15.2CPE matchmatch criteria | cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
An issue was discovered in D-Bus before 1.12.24 1.13.x and 1.14.x before 1.14.4 and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.
Oct 11, 2022dbus: dbus-daemon can be crashed by messages with array length inconsistent with element type
Oct 5, 2022